I have a universalforwarder running that picks up bluecoat logs from a directory. Everything works as expected, however every couple of hours theforwarder randomly crashes with the following e...
We're looking over our environment for potential safety flaws. One question that came up is whether an admin-user is available by default on Splunk UniversalForwarders (UF). I'm not thinking about...
Hi
My universalforwarder is taking about 30GB and my IT guys are asking is this normal.
I have just restarted it and then upgrade it to the latest 7.1.1, but with in 20 minutes it has gone f...
...md --reload
Five, I restarted theforwarder
./splunk restart in $Splunk_Home/bin
when the restart is finished, I'll check the splunk web page and I see that nothing happened aboutthe i...
...ores, 8gb memory, VMware VM)
Is there a way to improve performance/multithread theforwarder?
We've tried enabling parallelIngestionPiplines=2 in server.conf (This made theuniversalforwarder v...
...lan on having them connect to our network to send the data over at certain intervals.
We have thought about using theUniversalForwarder to do this, but it doesn't seem to send any of the data o...
...can not see any information about authentication. I have not added any SSL Cert, i guess this issue can be related to SSL communication between Forwarder and Reciever. But i just want to use the d...
HI,
Trying to install Linux auditD on universalforwarder. The app has been installed by support on Splunk Cloud.
The UF is installed on Syslog server and forwards data direct to Splunk Cloud, n...
...n their universalforwarder file manually, but it takes an hour or so before they forwardtheir logs. 4) The most recently added do not show their logs in real time i.e. when a time frame recently a...
I was hoping if someone can help me. We are looking into deploying Sysmon and theUniversalforwarder remotely in very specific circumstances ( suspicious activity on a host or by a user etc e...